Privacy Policy

Effective Date: July 2, 2025

Last Updated: August 3, 2025

⚠️ Important: Technical Implementation Status

This privacy policy describes our intended data protection practices. Some technical implementations are still in development.

  • Database encryption at rest is being implemented
  • Age verification systems are under development
  • Some data subject rights may have limited technical availability
  • International transfer safeguards are being enhanced

Contact info@reclaimed.health for current technical capabilities and implementation timelines.

Introduction

Reclaimed Health Ltd ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our family food safety app and related services for ingredient analysis and health guidance.

This policy applies to all users of our services, including our family food safety app, ingredient analysis tools, health guidance features, and website visitors who sign up for our waitlist.

Data Controller Information (Article 13/14 UK GDPR)

  • Identity: Reclaimed Health Ltd
  • Company Number: 15887887 (England and Wales)
  • Registered Address: Flat 15 Atrium Heights, 4 Little Thames Walk, London, England, SE8 3FB
  • Contact: info@reclaimed.health
  • Representative: Available upon request via info@reclaimed.health
  • Data Protection Officer: Ammar Jawad Doosh (CEO) - info@reclaimed.health
  • Purposes: Family food safety, ingredient analysis, health guidance, and waitlist management
  • Legal Basis: Legitimate interests, consent, contract performance, and vital interests (for health data)
  • Retention: As detailed in our retention policy below
  • Rights: Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent
  • Supervisory Authority: Information Commissioner’s Office (ICO) - ico.org.uk

Information We Collect

Information You Provide Directly

  • Family Information: Dietary preferences, allergy information, and household size (optional)
  • Contact Details: Name, email address, and account information
  • Ingredient Queries: Food products you scan and analyse using our app
  • Health Preferences: Dietary restrictions, allergy alerts, and ingredient preferences
  • Usage Data: Information about how you use our ingredient analysis features
  • Waitlist Information: Email address, knowledge level about ingredients/chemicals, concern level about health effects, and information sources that influence product decisions

Information Collected Automatically

  • Usage Analytics: How you interact with our ingredient analysis app and features
  • Technical Data: IP addresses, browser type, device information, and access times
  • Performance Metrics: App response times, scan frequency, and feature usage patterns
  • Error Logs: Technical issues and app performance data

Information from Third-Party Sources

  • Food Safety Databases: Publicly available information from FSA, EFSA, and other UK food safety authorities
  • Ingredient Information: Publicly available nutritional and safety data for food ingredients
  • Health Research: Published studies and guidelines on food safety and nutrition

How We Use Your Information

Primary Purposes

  • Ingredient Analysis: Providing AI-powered food ingredient analysis and safety guidance
  • Health Guidance: Offering personalised dietary and allergy alerts based on your preferences
  • Safety Notifications: Alerting families to potential health risks in food products
  • Product Recommendations: Suggesting safer alternatives based on your family’s needs
  • Service Improvement: Enhancing our AI models and app functionality
  • Waitlist Management: Managing notifications for product launches and updates
  • Market Research: Understanding user needs and preferences to improve our services

Legal Bases (UK GDPR)

  • Legitimate Interest: Providing food safety analysis and health guidance for UK families
  • Contract Performance: Delivering app services you’ve requested or subscribed to
  • Legal Obligation: Complying with food safety regulations and legal obligations
  • Consent: Where explicitly provided for specific data processing activities
  • Vital Interests: Processing health data to protect you and your family from serious health risks

Special Category Health Data (Article 9 UK GDPR)

Health Data Processing

  • Types of Health Data: Allergy information, dietary restrictions, health conditions affecting food choices
  • Legal Basis: Explicit consent and vital interests (protecting life and health)
  • Purpose: Preventing serious health risks from food allergens and harmful ingredients
  • Safeguards: Encrypted storage, access controls, regular audits, staff training
  • Consent Management: Granular consent options, easy withdrawal, clear explanations
  • Data Minimisation: Only collect health data necessary for safety warnings
  • Retention: Health data deleted within 30 days of account deletion unless legal retention required

Data Sharing and Disclosure

We Share Information With:

  • Service Providers: Cloud hosting, analytics, and technical support providers under strict data processing agreements
  • Waitlist Service Provider: GetWaitlist.com for managing waitlist signups and notifications
  • Hosting Platform: Vercel for website hosting and form submission processing
  • Regulatory Bodies: When legally required or to comply with regulatory investigations
  • Business Partners: With your explicit consent for specific collaborative services
  • Legal Advisors: For legal compliance and risk management purposes

Third-Party Data Processors

  • GetWaitlist.com: Processes and stores waitlist signup information including email addresses and user preferences
  • Vercel: Hosts our website and processes form submissions for waitlist signups
  • Data Processing Agreements: All third-party processors operate under strict data processing agreements that ensure UK GDPR compliance

We Do NOT Share:

  • Personal data with marketing companies
  • Confidential business information with competitors
  • Individual regulatory queries with third parties (except as legally required)
  • Proprietary business strategies or sensitive commercial information

Data Security and Protection

Technical Safeguards

  • Encryption: Data is encrypted in transit using industry-standard protocols. Database encryption at rest is being implemented as part of our ongoing security enhancements
  • Access Controls: Role-based access with multi-factor authentication
  • Security Monitoring: 24/7 monitoring for security threats and vulnerabilities
  • Regular Audits: Annual security assessments and compliance reviews

Organisational Measures

  • Staff Training: Regular privacy and security training for all team members
  • Data Minimisation: We collect and retain only necessary information
  • Privacy by Design: Privacy considerations built into all system designs
  • Incident Response: Established procedures for data breach response

Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Technical Implementation Timeline

We are implementing data subject rights progressively due to resource constraints (small development team, cloud migration requirements). Current status and timeline:

  • Currently Available: All rights via email requests to info@reclaimed.health (manual processing, 30-day response time)
  • Data Access & Portability: Automated export system (Q2 2025, 4-6 weeks development)
  • Data Rectification: Profile editing system (Q2-Q3 2025, 3-4 weeks development)
  • Data Erasure: Automated deletion system (Q3 2025, 4-5 weeks development)
  • Third-party Data: GetWaitlist.com data remains manual email process

Note: All rights remain fully exercisable via email throughout the implementation period. Technical automation will improve response times but does not affect your legal rights.

Access and Portability

  • Right of Access: Request a copy of all personal data we hold about you
  • Data Portability: Receive your data in a structured, machine-readable format

Correction and Deletion

  • Rectification: Correct inaccurate or incomplete personal data
  • Erasure: Request deletion of your personal data (subject to legal obligations)

Processing Controls

  • Restriction: Limit how we process your personal data
  • Objection: Object to processing based on legitimate interests
  • Withdrawal of Consent: Withdraw consent for specific processing activities

Automated Decision-Making

  • Right to Human Review: Request human review of AI-generated recommendations
  • Explanation: Understand how our AI agents reach their conclusions

Data Retention

Retention Periods

  • Active Accounts: Data retained while your account is active and for legitimate business purposes
  • Inactive Accounts: Data deleted after 3 years of inactivity (unless legal obligations require retention)
  • Waitlist Data: Email addresses and preferences retained until product launch and for 12 months after launch for marketing purposes
  • Regulatory Queries: Query logs retained for 2 years for service improvement
  • Legal Documents: Compliance records retained for 7 years as required by law

Deletion Process

  • Secure deletion using industry-standard data destruction methods
  • Certificate of destruction provided upon request
  • Regular purging of expired data according to retention schedules

Cookies and Tracking Technologies

Essential Cookies (Always Active)

  • reclaimed-health-cookie-consent: Stores your cookie preferences (Duration: 150 days)
  • reclaimed-health-cookie-preferences: Remembers your detailed cookie settings (Duration: Persistent)
  • next-auth.session-token: Maintains your login session (Duration: Session)
  • next-auth.csrf-token: Security protection against cross-site attacks (Duration: Session)
  • __vercel_live_token: Vercel deployment authentication (Duration: Session)

Analytics Cookies (Optional)

  • _ga: Google Analytics main cookie (Duration: 2 years)
  • _ga_*: Google Analytics property-specific cookie (Duration: 2 years)
  • _gid: Google Analytics session identifier (Duration: 24 hours)
  • _gat: Google Analytics throttling cookie (Duration: 1 minute)

Purpose: Help us understand app usage patterns and improve our family food safety features

Marketing Cookies (Optional)

  • _fbp: Facebook Pixel for conversion tracking (Duration: 3 months)
  • _gcl_au: Google Ads conversion tracking (Duration: 3 months)
  • _uetsid: Microsoft Advertising session tracking (Duration: Session)
  • _uetvid: Microsoft Advertising visitor tracking (Duration: 16 months)

Purpose: Show relevant ads about food safety to families who might benefit

Cookie Management

  • Granular Control: Choose exactly which cookies to accept through our cookie banner
  • Browser Settings: Control cookies through your browser preferences
  • Consent Withdrawal: Change your preferences anytime via our cookie settings
  • Regular Review: We review and update cookie usage every 6 months

International Data Transfers

UK Adequacy Decisions

  • Data transfers primarily within the UK and to countries with adequacy decisions
  • Appropriate safeguards in place for any international transfers
  • Regular assessment of international data protection standards

Transfer Safeguards

  • Standard Contractual Clauses: For transfers to non-adequate countries
  • Binding Corporate Rules: For transfers within multinational organisations
  • Certification Schemes: Additional protection through recognised certification
  • Third-Party Processor Compliance: GetWaitlist.com and Vercel maintain appropriate safeguards for international data transfers

Waitlist Services

GetWaitlist.com Integration

We use GetWaitlist.com, a third-party service, to manage our product waitlist:

  • Data Collected: Email addresses, knowledge levels about ingredients/chemicals, concern levels about health effects, and information sources that influence purchasing decisions
  • Purpose: Notify users when our products become available and understand user needs
  • Legal Basis: Consent (you can unsubscribe at any time)
  • Data Location: GetWaitlist.com processes data in accordance with UK GDPR requirements
  • Retention: Data retained until product launch and for 12 months thereafter unless you unsubscribe

Vercel Hosting

Our website and waitlist forms are hosted on Vercel:

  • Data Processing: Form submissions and website analytics
  • Security: Industry-standard encryption and security measures
  • Compliance: Vercel maintains SOC 2 compliance and appropriate data protection safeguards
  • Data Location: Primarily EU/UK with appropriate transfer safeguards where applicable

Your Rights for Waitlist Data

  • Unsubscribe: Use the unsubscribe link in any email or contact us directly
  • Access: Request a copy of your waitlist data
  • Deletion: Request immediate deletion of your waitlist information
  • Correction: Update your preferences or correct inaccurate information

Children’s Privacy and UK Age Appropriate Design Code

Our family food safety app is designed to help parents protect their children, but we take children’s privacy extremely seriously:

Age Restrictions and Verification

  • Minimum Age: Service is restricted to users aged 18 and over
  • Age Verification: Technical age verification systems are under development. Users under 18 should not use this service until proper verification is implemented
  • Parental Accounts: Parents can create accounts to manage their family’s food safety
  • Child Data Protection: We never directly collect data from children under 16

UK Age Appropriate Design Code Compliance

  • Privacy by Default: Highest privacy settings applied by default
  • Data Minimisation: Collect only essential data for food safety purposes
  • Parental Controls: Parents maintain full control over family safety settings
  • Transparent Processing: Clear, child-friendly explanations when applicable
  • No Profiling: We do not create behavioural profiles of children
  • Safety Focus: All processing prioritizes child safety over commercial interests

Family Data Protection Measures

  • Indirect Collection: Any data about children collected only through parent accounts
  • Health Data: Child allergy information processed only with explicit parental consent
  • Immediate Deletion: Child data deleted immediately upon account closure
  • No Marketing: Children under 16 never receive direct marketing communications
  • Regular Reviews: Quarterly assessments of child data processing practices

Privacy by Design

Built-in Protection

  • Data Minimisation: Collect only necessary information
  • Purpose Limitation: Use data only for stated purposes
  • Storage Limitation: Retain data only as long as necessary
  • Accuracy: Maintain accurate and up-to-date information

Proactive Measures

  • Regular privacy impact assessments
  • Privacy considerations in all system updates
  • Continuous monitoring of data processing activities
  • Regular training on privacy best practices

Updates to This Policy

Change Management

  • Material changes communicated 30 days in advance
  • Minor updates reflected immediately with notification
  • Version control and change history maintained
  • Annual review and update process

Notification Methods

  • Email notification to registered users
  • Prominent website notices for significant changes
  • In-app notifications for active users
  • Archive of previous policy versions available

Contact Information

Data Protection Officer

Email: info@reclaimed.health

Address: Reclaimed Health Ltd, London, United Kingdom

Phone: Available via email contact

General Inquiries

Support: info@reclaimed.health

Legal: info@reclaimed.health

Security: info@reclaimed.health

Supervisory Authority

If you have concerns about our data processing, you can contact:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Phone: 0303 123 1113

Legal Framework Compliance

UK GDPR Compliance

  • Full compliance with UK General Data Protection Regulation
  • Regular compliance audits and assessments
  • Documented lawful bases for all processing activities
  • Privacy impact assessments for high-risk processing

Additional Regulations

  • Consumer Rights Act 2015: Transparent information about data use
  • Computer Misuse Act 1990: Security measures and access controls
  • Electronic Communications Regulations: Email marketing and communications
  • Financial Services Regulations: Where applicable to financial advice features

Artificial Intelligence and Automated Processing

AI Decision-Making

  • Transparency: Clear explanation of how our AI agents work
  • Human Oversight: Human review available for all AI recommendations
  • Bias Prevention: Regular testing and monitoring for algorithmic bias
  • Accuracy Measures: Continuous improvement of AI model accuracy

Data Use in AI Training

  • Aggregated and anonymized data used for model improvement
  • Opt-out options for sensitive business information
  • Separate consent for AI training data use
  • Regular audits of AI training data usage

This privacy policy is designed to comply with UK data protection law and provide transparency about our data practices. If you have any questions or concerns, please contact our Data Protection Officer using the details provided above.

Document Version: 1.0

Review Date: July 2, 2026

Classification: Public Document